Use this procedure to enable the Quantum-Safe Security app to build a cryptographic
inventory, identify vulnerable assets, track PQC readiness, and share migration
recommendations.
| Where Can I Use This? | What Do I Need? |
The Quantum-Safe Security app provides visibility into your cryptographic
posture and offers remediation guidance to support the
transition to post-quantum cryptography
(PQC). The app features an inventory of your network assets and their
cryptographic components and an interactive dashboard that provides a high-level
overview of cryptographic risk and quantum readiness across the
enterprise. To
discover assets and provide actionable insights, the app continuously ingests
telemetry from your Next-Generation Firewalls (NGFW), Prisma Access tenants, and
integrated third-party solutions through the Strata Logging Service. You must
onboard your NGFWs and Prisma Access tenants to the Strata Logging Service and
enable them to forward device telemetry and logs. The app only evaluates data from
onboarded devices.
Decryption logs are the primary data source for the app because they
capture critical cryptographic metadata, including algorithms, protocol versions,
and certificates in use. For comprehensive visibility, log both successful and
unsuccessful TLS handshakes from both traffic you decrypt and traffic you choose not
to decrypt.
If you have
Device Security licenses, ensure the
licenses and enabled devices are associated with your Strata Logging Service
instance. Device Security identifies end-user, IoT, and operational technology (OT)
devices and streams device data to the Strata Logging Service. This enriches your
assets with additional context, such as the operating system, hardware model, and
vendor. The Quantum-Safe Security app uses this context to evaluate quantum
readiness and generate hardware and software upgrade recommendations.
Complete the following steps to enable the Quantum-Safe Security app to
collect the data it needs to populate your inventory and dashboard. This procedure
assumes you are configuring policy rules on Strata Cloud Manager rather than on
individual NGFWs.